Page MenuHomePhabricator

Consider removing passphrases from deployment-prep's ssh keys used by `keyholder`
Open, Needs TriagePublicFeature

Description

T385822: Document post-restart activities needed across deployment-prep services flags arming keyholder as a thing humans have to remember to do when the deployment-deployment* instances are rebooted. The passphrases in deployment-prep are of dubious value in that they protect use of an ssh key that really doesn't do anything that normal deployment-prep project members can't already do themselves. Can we remove the passphrases from the private keys so that they are automatically loaded by keyholder on startup?